[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fprNijdhuAfsfE9LkgTCsgDRFeg1wlfeccRMPvcwATAw":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":44},"cbda1a4c-1892-4428-a8c9-f3561d3d0bb7","fake-passkey-enrollment-scam-hijacks-microsoft-365-accounts","4aad1e57-f9f9-4ee5-81bc-5176dcdc9483","Fake Passkey Enrollment Scam Hijacks Microsoft 365 Accounts","Threat actor O-UNC-066 is exploiting user trust through voice phishing (vishing) combined with a custom phishing kit to manipulate victims into enrolling attacker-controlled passkeys into their Microsoft 365 accounts. Once enrolled, the attacker gains persistent, legitimate-looking access without needing the victim's password, bypassing traditional MFA protections. This attack is particularly dangerous because passkeys are widely perceived as a secure authentication method, making users less likely to question the enrollment process. The campaign highlights how social engineering can undermine even modern authentication technologies when users are not trained to recognize manipulation tactics. Organizations face serious data extortion risk if employees cannot identify and resist these sophisticated vishing scenarios.","**Immediate actions:**\n- Train all employees to recognize vishing tactics and establish a verified callback procedure before performing any account security actions requested via phone.\n- Enforce a policy requiring users to initiate passkey or MFA device enrollment only through official, self-service portals — never at the direction of an inbound caller.\n- Review Microsoft Entra audit logs immediately for any unexpected passkey or authentication method enrollments across all accounts.\n\n**Long-term improvements:**\n- Implement Conditional Access policies in Microsoft Entra ID that restrict new authentication method registrations to trusted networks or require admin approval.\n- Deploy a phishing-resistant MFA strategy that includes user education on passkey security and the risks of social-engineering-driven enrollment.\n- Establish a formal identity governance process with periodic reviews of registered authentication devices for all privileged and standard user accounts.\n\n**Detection measures:**\n- Configure alerts in Microsoft Entra ID and your SIEM for new passkey or authentication method enrollments, especially outside business hours or from unfamiliar locations.\n- Monitor for anomalous login patterns following any new device or passkey registration as an indicator of account compromise.\n- Integrate threat intelligence feeds covering phishing kits and vishing campaigns targeting Microsoft 365 to enable proactive detection.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 4 – Secure Configuration of Enterprise Assets","CIS Control 5 – Account Management","CIS Control 6 – Access Control Management","CIS Control 14 – Security Awareness and Skills Training","NIST SP 800-63B – Digital Identity Guidelines (Authentication)","NIST AC-2 – Account Management","NIST IA-5 – Authenticator Management","NIST AT-2 – Literacy Training and Awareness","NIST SI-4 – System Monitoring","GDPR Article 32 – Security of Processing","ISO\u002FIEC 27001 A.9.4 – System and Application Access Control","Microsoft Zero Trust Identity Pillar – Verified Identity","published","2026-07-10T12:22:23.638717+00:00","2026-07-10T12:22:23.358+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fhackers-use-fake-microsoft-entra.html","hackers-use-fake-microsoft-entra-passkey-enrollment-to-gain-microsoft-365-access-44e86b","Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 Access",[32,38],{"id":33,"name":34,"slug":35,"description":36,"color":37},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":39,"name":40,"slug":41,"description":42,"color":43},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]